modifed win_susp_msoffice.yml

This commit is contained in:
root 2019-10-26 07:55:44 +02:00
parent fc7f8ecea3
commit bea2daac45

View File

@ -19,7 +19,8 @@ detection:
Image:
- '*\powerpnt.exe'
- '*\winword.exe'
CommandLine: '* "http*'
- '*\excel.exe'
CommandLine: '* http*'
condition: selection
level: medium
falsepositives: